We value your privacy

We use cookies to analyze site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Microsoft Intune
  2. Android Enterprise
Android Enterprise management

Wiping the phone is mandatory for three of the five Android enrollment methods. Decide before the purchase order goes out.

Wiping the device is a precondition for corporate-owned work profile, for fully managed, and for dedicated device enrollment. The personally owned work profile is the one route that skips it. Settle which method applies while the handsets are still on a purchase order and the rollout is uneventful; settle it afterward and somebody has to explain why four hundred phones already in use are about to be erased.

Book an Android enrollment reviewSee the enrollment methods
Android phones and handhelds managed across a US organization
  • Factory resetRequired for three of the five methods
  • 15 devicesEnrollment limit for a standard account
  • 1,000 devicesLimit with a device enrollment manager
  • DeprecatedDevice administrator, on Google services devices
The decision that cannot be undone cheaply

Factory reset, and which methods require one.

Microsoft publishes this as a table, and it is the single fact that should govern your enrollment choice before a device is bought or handed out.

  • Nothing gets erased under two routes: the Android Enterprise personally owned work profile, and the deprecated device administrator method. Because a phone somebody is already using can take either one, personally owned work profile is the realistic answer whenever the employee owns the hardware.
  • Three routes start with a wipe: corporate-owned work profile, fully managed, and dedicated devices. All three assume company ownership, and all three mean anything currently in an employee's hands has to be erased before it can reach that state.
  • A second published detail deserves attention. Devices enrolling without a reset start pulling Intune policy straight away, and any setting you have not configured in Intune beforehand simply stays as it was. The device carries its previous configuration in with it.
  • The practical upshot is that the decision belongs at the purchasing stage. When hardware is bought and distributed before anyone picks an enrollment method, the fleet usually ends up on the wrong one, because no organization is willing to erase hundreds of phones that people already use and keep personal data on.
Ask us to choose the method before you buy
The enrollment methods

Eight facts that shape how an Android deployment goes.

Where handsets carry Google Mobile Services, Microsoft points at the Android Enterprise routes; where corporate hardware ships without them, at the Android Open Source Project options. Whichever you land on, none of the Android Enterprise routes function until Intune is connected to a managed Google Play account.

The factory reset requirement, which shapes everything

The published position leaves no ambiguity: corporate-owned work profile, fully managed and dedicated device enrollment each begin with wiping the handset. Personally owned work profile does not, and neither does the deprecated device administrator route. A stack of sealed boxes and a fleet already in people's pockets are therefore two completely different projects, which is why the choice belongs to procurement rather than to whoever configures the console later.

The work profile route for hardware the employee bought

A separate work profile is created on the employee's own handset so personal and work applications sit side by side and switch easily and securely, with the owner running enrollment from the Company Portal. Your authority stops at the applications and data inside that profile. Nothing gets wiped to set it up, which is precisely why this is the route that works on phones people already carry.

Corporate-owned work profile, for company phones people also use personally

Microsoft frames this one as corporate hardware that is also approved for personal use, with a distinct work profile the employee moves in and out of. It fits the common American arrangement where the company buys the phone and nobody seriously expects it to stay work-only. In our experience it is the method most organizations ought to be running and comparatively few actually are.

Fully managed, for devices that are only for work

Corporate hardware dedicated entirely to work, with a single associated user. Microsoft notes that this method opens up management of the whole device along with policy controls the work profile route cannot reach. The exchange is genuine: you gain that control and you give up any space for personal use, which people will attempt regardless unless the policy is stated plainly and the culture backs it.

Dedicated devices, for the ones nobody personally owns

Single-purpose and kiosk hardware owned by the company, with digital signage, ticket printing and inventory management named directly as the intended uses. You constrain which applications and web links exist and keep the device from being used for anything outside its assigned job, which describes an enormous amount of the equipment on American shop floors, loading docks and hotel front desks.

AOSP methods, for devices with no Google services at all

Corporate hardware built on the Android Open Source Project without Google Mobile Services has two routes of its own. One covers userless devices with nobody assigned, meant to be shared the way equipment in a library or lab is shared. The other ties a device to one person for work-only use. Ruggedized and purpose-built handsets land here constantly.

Zero-touch, which Microsoft recommends for volume

For bulk enrollment, and for getting remote staff onto managed devices without a technician in the room, zero-touch is the recommended approach: hardware is staged in advance so that powering it on provisions and enrolls it as fully managed automatically. Any company shipping phones to employees scattered across the country is choosing between this and paying somebody to touch every handset.

Device administrator is deprecated, and it is time to move

On any handset with access to Google Mobile Services, device administrator management is deprecated and no longer available, and Microsoft's guidance is to move to one of the other Android options. What remains is support and documentation covering some Android 15 and earlier devices that lack Google services. If your Android fleet still sits on this method, the migration is something to schedule rather than postpone.

How we approach it

Four decisions that separate a smooth Android deployment from a painful one.

No other platform punishes an early wrong turn this severely, for the simple reason that three of its enrollment routes cannot be taken without erasing the device.

We choose the enrollment method before devices are bought

Because corporate-owned work profile, fully managed and dedicated all start with a wipe, making the call during procurement means hardware shows up and enrolls correctly the first time. Leave it until later and the options narrow to erasing phones people already depend on, with the personal-data conversation that follows, or accepting a method that delivers less than the licensing entitles you to.

Company handsets usually belong on the corporate-owned work profile

Microsoft positions it for company hardware that is also approved for personal use, with a separate work profile the employee switches between. Pretending an American company phone will only ever be used for work produces either resentment or a second handset in the same pocket. This method is the configuration that matches reality while still leaving you genuine control.

We stage bulk enrollment correctly, account ceilings included

Fifteen devices is the ceiling on an ordinary non-administrator account; a device enrollment manager account reaches a thousand. Hitting that wall at device sixteen, midway through staging a shipment, is an entirely preventable afternoon. Where the supplier supports it, zero-touch is Microsoft's recommended answer for volume and for remote staff.

We schedule the exit from device administrator instead of postponing it

Deprecated and unavailable on handsets with Google Mobile Services, with Microsoft advising a move to another option, device administrator is a method with no future. Fleets still sitting on it are running out of road. Scheduling the move to Android Enterprise on your own timetable costs considerably less than being pushed into it by a hardware refresh nobody planned.

Where this matters most

Six US situations where Android management decisions matter.

Frontline and operational roles run on Android almost everywhere, and that half of the fleet is reliably the half nobody has managed properly.

Logistics and delivery operations with rugged handsets

Barcode scanners, driver handsets and hardened field units, a great many of which ship without Google Mobile Services. The Android Open Source Project routes exist for exactly this hardware, userless where devices are shared and user-associated where one person keeps one unit. Choose correctly and you have a managed fleet; choose otherwise and you have equipment nobody can patch or lock.

Retail and hospitality with single-purpose devices

Menu boards, ticket printers, ordering terminals and stock-count units, all named in the dedicated device use cases. Restricting which applications and web links exist, and blocking anything outside the assigned job, is what keeps a customer-facing tablet from quietly becoming a general-purpose browser on the counter.

A company phone fleet where personal use is a fact

Company-purchased Android handsets that employees also use personally, which is how company phones function in the real world. Corporate-owned work profile was designed for this exact case, keeping work applications and data separate and governable while leaving the personal side untouched, and it avoids the fiction a fully managed deployment would require.

A regulated firm needing control over company devices

Where GLBA, the FTC Safeguards Rule, HIPAA or an insurance policy demands real authority over corporate hardware, fully managed enrollment delivers control of the entire device plus policy options the work profile route does not expose. In exchange personal use disappears, and that has to be published as policy rather than discovered by an employee whose photo app vanished.

A large distribution of new devices to remote staff

Hundreds of handsets heading to people in different states who will never set foot in an office. Zero-touch is the recommended answer for exactly this: stage the hardware ahead of time and each device provisions and enrolls as fully managed the moment its new owner powers it on. Otherwise somebody is unboxing every unit before it ships.

An estate still on Android device administrator

Deprecated on anything carrying Google Mobile Services, with documentation surviving only for certain Android 15 and earlier devices that lack Google services. The destination is not in question and there is no alternative route, so pairing the migration with a planned hardware refresh is far cheaper than executing it against a deadline somebody else sets.

Three positions

How Android devices actually get managed in US organizations.

The middle column turns up most often and reads worst: company hardware enrolled through a method built for personal phones, chosen because nobody wanted to erase anything, leaving the business with less control than its licenses already paid for.
Enrollment method matches device ownership
Right method, chosen firstYes
Whatever avoided a wipeNo
Unmanaged or device administratorNo
Bulk enrollment through zero-touch
Right method, chosen firstYes
Whatever avoided a wipeRarely
Unmanaged or device administratorNo
Full device policy control where owned
Right method, chosen firstYes
Whatever avoided a wipeNo
Unmanaged or device administratorPartly
Personal data separated from work data
Right method, chosen firstYes
Whatever avoided a wipeYes
Unmanaged or device administratorNo
Kiosk and single-use devices locked down
Right method, chosen firstYes
Whatever avoided a wipeNo
Unmanaged or device administratorNo
Devices without Google services supported
Right method, chosen firstYes, via AOSP
Whatever avoided a wipeNo
Unmanaged or device administratorNo
On a supported management method
Right method, chosen firstYes
Whatever avoided a wipeYes
Unmanaged or device administratorDeprecated
Enrollment restrictions configured
Right method, chosen firstYes
Whatever avoided a wipeRarely
Unmanaged or device administratorNo
Bulk enrollment limits understood
Right method, chosen firstYes
Whatever avoided a wipeDiscovered at device 16
Unmanaged or device administratorNot applicable
How common this is in practice
Right method, chosen firstUncommon
Whatever avoided a wipeCommon
Unmanaged or device administratorCommon
Feature
Right method, chosen first
Whatever avoided a wipe
Unmanaged or device administrator
Enrollment method matches device ownership
YesNoNo
Bulk enrollment through zero-touch
YesRarelyNo
Full device policy control where owned
YesNoPartly
Personal data separated from work data
YesYesNo
Kiosk and single-use devices locked down
YesNoNo
Devices without Google services supported
Yes, via AOSPNoNo
On a supported management method
YesYesDeprecated
Enrollment restrictions configured
YesRarelyNo
Bulk enrollment limits understood
YesDiscovered at device 16Not applicable
How common this is in practice
UncommonCommonCommon
The methods compared

Every enrollment route, the hardware it fits, and whether it erases the handset.

Drawn from the published method descriptions and the factory reset table. In practice the reset column decides what is realistically achievable more often than any capability difference does.

Method

Personally owned work profile

Suits, and whether a reset is required
Employee-owned handsets in BYOD scenarios. Nothing is erased.

Method

Corporate-owned work profile

Suits, and whether a reset is required
Company hardware that is also approved for personal use. Wipe first.

Method

Fully managed

Suits, and whether a reset is required
Company hardware, work only, one user each, deepest policy control. Wipe first.

Method

Dedicated device

Suits, and whether a reset is required
Kiosk and single-purpose units, signage, ticket printing, inventory. Wipe first.

Method

AOSP userless

Suits, and whether a reset is required
Shared hardware with no Google services and nobody assigned. Rugged and purpose-built units.

Method

AOSP user associated

Suits, and whether a reset is required
Hardware without Google services, tied to one person, work only.

Method

Zero-touch enrollment

Suits, and whether a reset is required
The recommended path for bulk and remote staff, provisioning as fully managed at first power-on.

Method

Device administrator

Suits, and whether a reset is required
Deprecated, and unavailable wherever Google Mobile Services are present. Schedule the migration.
MethodSuits, and whether a reset is required
Personally owned work profileEmployee-owned handsets in BYOD scenarios. Nothing is erased.
Corporate-owned work profileCompany hardware that is also approved for personal use. Wipe first.
Fully managedCompany hardware, work only, one user each, deepest policy control. Wipe first.
Dedicated deviceKiosk and single-purpose units, signage, ticket printing, inventory. Wipe first.
AOSP userlessShared hardware with no Google services and nobody assigned. Rugged and purpose-built units.
AOSP user associatedHardware without Google services, tied to one person, work only.
Zero-touch enrollmentThe recommended path for bulk and remote staff, provisioning as fully managed at first power-on.
Device administratorDeprecated, and unavailable wherever Google Mobile Services are present. Schedule the migration.
How a deployment runs

Five steps, and step one sets the price of everything after it.

Three to six weeks is typical, driven by fleet size and by whether hardware has already been handed out. The wipe requirement is what makes sequence matter so much here.
  1. 1

    Choose the enrollment method per population

    Employee-owned handsets, company phones that double as personal ones, work-only hardware, single-purpose units and devices without Google services each resolve differently. This step lands before procurement or distribution, because three of the methods cannot be applied later without erasing the device.

  2. 2

    Connect managed Google Play and set restrictions

    The managed Google Play connection is a hard prerequisite for every Android Enterprise option. With that in place, configure enrollment restrictions by platform, version, manufacturer or ownership type, set device limits, and add terms and conditions if you want them presented in the Company Portal before anyone enrolls.

  3. 3

    Prepare bulk enrollment properly

    Zero-touch wherever the supplier offers it, since it is the recommended route for volume and for remote staff. Device enrollment manager accounts wherever hardware is staged centrally, given that an ordinary non-administrator account stops at fifteen devices while a device enrollment manager reaches a thousand.

  4. 4

    Build the policy set for each method

    Available controls differ between work profile, fully managed and dedicated device enrollment, so configuration profiles, compliance rules and application assignments have to be authored per method. Writing one policy set for a method it was never designed for is the usual origin of the complaint that Android management does not work.

  5. 5

    Pilot, then distribute

    Start with a small group spanning every method in scope and walk the enrollment experience end to end, including what the employee sees inside the Company Portal. The report covering incomplete and abandoned enrollments shows where people stalled, and it is worth reading during the pilot rather than after the fleet has shipped.

Straight answers

What organizations ask about Android Enterprise.

Ownership answers most of it, and whether personal use is permitted answers the rest. Employee-owned handsets take the personally owned work profile. Company phones that double as personal ones take corporate-owned work profile. Work-only company hardware takes fully managed. Kiosk and single-purpose units take dedicated. Anything without Google Mobile Services takes one of the two Android Open Source Project routes. The set of controls available to you differs in each case.

Under three of the five methods it will. The published table shows corporate-owned work profile, fully managed and dedicated device enrollment each requiring a factory reset, while the personally owned work profile and the deprecated device administrator route do not. That is the fact to design around, and the decision needs making before hardware is distributed rather than after somebody counts how many phones would have to be erased.

That is exactly what the personally owned work profile does. Enrollment builds a separate work profile so the employee moves between personal and work applications easily and securely, they run the process themselves from the Company Portal, and your authority covers the applications and data inside that profile only. Personal apps and personal data sit outside your reach by design, which is also the posture that holds up best against American employee privacy expectations and state monitoring-notice laws.

Whether personal use is on the table. Corporate-owned work profile covers company hardware also approved for personal use, keeping a distinct work profile the employee switches into. Fully managed covers company hardware used purely for work, with one associated user, and Microsoft notes it unlocks management of the entire device plus policy controls the work profile method cannot offer. More reach, no personal use.

The Android Open Source Project routes exist for precisely that hardware. Two are available: corporate-owned userless devices, which carry no assigned user and are intended for shared use of the kind you see in a library or a lab, and corporate-owned user-associated devices, tied to one person and used only for work. Ruggedized handsets and purpose-built terminals land in this category regularly.

Not on hardware with Google services. That management method is deprecated and no longer available for devices with access to Google Mobile Services, and Microsoft recommends switching to one of the other Android options. What continues is support and documentation for some Android 15 and earlier devices without Google services. Any fleet still running on it should have a migration on the calendar.

Intune connected to your managed Google Play account, which is mandatory across every Android Enterprise option, personally owned work profile, corporate-owned work profile, fully managed and dedicated alike. Separately, any handset currently enrolled in another mobile device management product needs removing from that platform before it comes into Intune.

Two mechanisms, used together. Zero-touch enrollment is the recommended route for bulk work and for simplifying enrollment for remote staff, staging hardware in advance so it provisions and enrolls as fully managed at first power-on. Alongside it, device enrollment manager accounts exist because an ordinary non-administrator account tops out at fifteen devices while a device enrollment manager handles up to a thousand.

Fifteen is the cap on a standard non-administrator account, and staging teams collide with it constantly. The fix is a device enrollment manager account, a non-administrator Microsoft Entra user permitted to enroll as many as a thousand company-owned devices. Note that certain methods, Apple automated device enrollment among them, are not compatible with that account type.

Enrollment restrictions handle this. Platform restrictions filter by platform, version, manufacturer or ownership type, and device limit restrictions cap how many devices any one person can bring in. Both belong in place before enrollment opens, and both are routinely left at their defaults, which is how fleets accumulate hardware nobody ever agreed to support.

Yes, through a Conditional Access policy carrying a multifactor requirement, which Microsoft notes depends on Microsoft Entra ID P1 or P2. Since enrollment is the moment a device acquires a trusted identity in your tenant, asking for a second factor at that point is proportionate, and it happens to be one of the tenant-level controls insurance questionnaires reward.

Device categories do the sorting. Create a category in Intune and devices assigned to it are added automatically to the matching device group. Across a fleet spanning several enrollment methods and several populations that removes a great deal of manual group maintenance. The capability covers every platform except Linux.

This is called out specifically for the methods that skip the reset: those devices begin installing Intune policy as soon as they enroll, and any setting you have not configured in Intune beforehand remains exactly as it was. The device brings its history along, so it is worth inspecting rather than assuming enrollment hands you a clean slate.

A dedicated report covers incomplete and abandoned user enrollments, showing where inside the Company Portal people failed to finish the process. Through a pilot and the opening weeks of a rollout it is the most useful view available, because it separates the population that tried and could not complete enrollment from the population that has not started yet.

Scoped per engagement, shaped by fleet size, by how many enrollment methods are in play, and by whether hardware has already gone out, since that last point decides whether a factory reset is a plan or a crisis. At no charge, the first conversation will tell you which enrollment method your circumstances actually call for, because that is the decision where being wrong costs real money.
Before enrolling anything

Fifteen questions worth answering first.

Answer the first group and the method picks itself. The second covers groundwork most rollouts discover late. The third holds the practical ceilings, one of which halts a bulk enrollment without warning.

Choosing the method

  • Who owns the devices?
    Everything else branches from this answer.
  • Are the devices already in use?
    Three methods begin by erasing the handset.
  • Is personal use allowed on company phones?
    This separates corporate-owned work profile from fully managed.
  • Do the devices have Google Mobile Services?
    Without them, the AOSP routes are the only option.
  • Are you still using device administrator?
    Deprecated wherever Google services are present.

Preparation

  • Is Intune connected to managed Google Play?
    No Android Enterprise option works without it.
  • Are devices currently enrolled elsewhere?
    Remove them from the incumbent platform first.
  • Have you set enrollment restrictions?
    Available by platform, version, manufacturer or ownership.
  • Do you need terms and conditions shown?
    They appear in the Company Portal ahead of enrollment.
  • Should MFA apply at enrollment?
    Through Conditional Access, which needs Entra ID P1 or P2.

The practical limits

  • How many devices is one person enrolling?
    Ordinary accounts stop at 15.
  • Do you need a device enrollment manager?
    That account type reaches 1,000.
  • Is zero-touch available from your supplier?
    The recommended route for volume and remote staff.
  • Do you want devices auto-grouped by category?
    Categories drop devices into matching groups automatically.
  • Who reviews abandoned enrollments?
    A report shows where people gave up partway.
Related reading

The pages around this one.

Microsoft Intune

The platform underneath all of this, covering configuration, compliance and application delivery on every supported platform.

Learn more

Kiosk and shared devices

A closer look at the dedicated device route: signage, terminals and shift-shared handhelds pinned to one job.

Learn more

MDM solutions

The wider view across Windows, Apple and Android, and how to choose between the available approaches.

Learn more
Next step

Settle the enrollment method while the phones are still on order.

Three of the five routes begin by erasing the handset, and that is not something you can retrofit onto hardware people already rely on. Thirty minutes spent on this at the purchasing stage avoids a conversation nobody enjoys having later.

Book an Android enrollment reviewSee device enrollment design

Related Services

Explore more solutions that work great with this service

Microsoft Intune

Device management and endpoint security

Learn more

Mobile Threat Defense with Intune

Mobile Threat Defense integration for US organizations: selecting one

Learn more

Endpoint Security

Endpoint security for US businesses using Microsoft Defender for

Learn more
GR IT SERVICES

IT services for US businesses,
delivering enterprise-grade solutions
remotely, coast to coast.

Microsoft CSP PartnerApple Jamf PartnerCISGuard

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support USA
  • IT AMC USA
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • hello@gritservices.io
  • gritservices.io

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie PolicyCCPA/CPRA